Electronic information storage medium and wireless communication network connection method
The SIM-based solution for connecting terminals to multiple wireless networks addresses the challenges of key management and network transitions by using signature verification and counters, ensuring secure and efficient network switching.
Patent Information
- Application Number
- JP2021126717
- Authority / Receiving Office
- JP · JP
- Patent Type
- Patents
- Current Assignee / Owner
- Filing Date
- 2021-08-02
- Publication Date
- 2026-01-06
- Estimated Expiration
- 2041-08-02
AI Technical Summary
Existing methods for connecting terminals to wireless communication networks in mixed environments, such as private LTE and local 5G, face challenges due to the unavailability of SMS communication and the burdensome management of shared keys, particularly in private networks with many small players.
An electronic information storage medium, such as a SIM, equipped with a key pair and authentication mechanisms, allows terminals to connect to desired networks through signature verification and counter-based security, minimizing key management efforts.
Enables secure connection to wireless networks without relying on SMS, reducing key management complexity and ensuring network transitions are efficient and secure.
Smart Images

Figure 0007793904000001 
Figure 0007793904000002 
Figure 0007793904000003
Abstract
Description
[Technical Field]
[0001] The present invention relates to the technical field of a SIM (Subscriber Identity Module) and the like that is mounted on a terminal that can connect to any one of a plurality of different wireless communication networks. [Background technology]
[0002] Conventionally, a method for a terminal to connect to a desired wireless communication network in an area where multiple wireless communication networks (e.g., 3G, LTE, 5G, etc.) are mixed is known, which uses a REFRESH command of a SIM installed in the terminal. This method uses a Secured Packet format SMS (Short Message Service) message defined by the Third Generation Partnership Project (3GPP), as shown in Patent Document 1, for example, and performs an appropriate authentication process to prevent pranks and service disruptions. In this authentication process, a common key is shared between an external device and the SIM, and the SIM uses the common key to verify the signature of a received SMS message and confirm the authenticity of the message. [Prior art documents] [Patent documents]
[0003] [Patent Document 1] Japanese Patent Application Laid-Open No. 2017-76930 Summary of the Invention [Problem to be solved by the invention]
[0004] However, in private wireless communication networks (private LTE and local 5G), which are being increasingly considered for use, cheaper network equipment is used, and SMS communication and Secured Packets using SMS communication are often not available. Also, the authentication process using the above-mentioned shared key requires a lot of effort to distribute and manage the shared key, which places a burden on administrators in private wireless communication networks with many relatively small players.
[0005] Therefore, the present invention has been made in consideration of the above points, and aims to provide an electronic information storage medium and a program that are capable of connecting a terminal to a desired wireless communication network without relying on a specific communication method such as SMS, and while minimizing the effort required for key management and ensuring security. [Means for solving the problem]
[0006] In order to solve the above problem, the invention described in claim 1 is an electronic information storage medium mounted on a terminal that can connect to any one of a plurality of different wireless communication networks, the electronic information storage medium comprising: a storage means for storing a public key included in a key pair unique to the external device; and a storage means for storing a public key included in a key pair unique to the external device, the storage means being configured to connect to a predetermined wireless communication network among the plurality of wireless communication networks. Finger and signature information generated by signing the instruction information with a private key included in the key pair, the instruction information and the signature information being transmitted from the external device, the reception means receiving the instruction information and the signature information via an information processing unit of the terminal; authentication means performing signature verification using the public key and the signature information in response to the instruction information; and authentication means connecting to the predetermined wireless communication network when the signature verification is successful. Ruko and a transmitting means for transmitting the command to the information processing unit of the terminal.
[0007] The invention of claim 2 is the electronic information storage medium of claim 1, further comprising a counter that holds a counter value transmitted from the information processing unit, wherein the receiving means receives the counter value together with the instruction information and the signature information, the authenticating means determines whether the counter value received by the receiving means is greater than the counter value held in the counter, and the transmitting means connects to the predetermined wireless communication network when it is determined that the signature verification is successful and the counter value received by the receiving means is greater than the counter value held in the counter. Ruko The command is transmitted to the information processing unit of the terminal.
[0008] The invention described in claim 3 is characterized in that, in the electronic information storage medium described in claim 1 or 2, the instruction information and the signature information are received by the terminal via short-range wireless communication performed between the terminal and the external device when a user carrying the terminal enters a specific area.
[0012] Claim 4 The invention described in claims 1 to 3 In the electronic information storage medium described in any one of the above, the predetermined wireless communication network is a private wireless communication network other than a public communication network provided by a mobile communication carrier.
[0013] Claim 5 The invention described in claims 1 to 3 2. The electronic information storage medium according to claim 1, wherein the command is to switch the terminal from a wireless communication network to which the terminal is currently connected to the predetermined wireless communication network. Ruko It is characterized by being a command.
[0014] Claim 6The invention described in the document is a wireless communication network connection method performed by an information processing unit of a terminal that can connect to any one of a plurality of different wireless communication networks and an electronic information storage medium mounted on the terminal, the method comprising the steps of: the electronic information storage medium storing a public key included in a key pair unique to an external device; and the information processing unit of the terminal connecting to a predetermined wireless communication network among the plurality of wireless communication networks. Finger receiving, from the external device, instruction information indicating an instruction to be performed and signature information generated by signing the instruction information with a private key included in the key pair, and transmitting the received instruction information and signature information to the electronic information storage medium; when the electronic information storage medium receives the instruction information and the signature information from the information processing unit of the terminal, performing signature verification using the public key and the signature information; and when the signature verification is successful, connecting the electronic information storage medium to the predetermined wireless communication network. Ruko and when the information processing unit of the terminal receives the command from the electronic information storage medium, the information processing unit of the terminal connects to the specified wireless communication network. [Effects of the Invention]
[0016] According to the present invention, it is possible to connect a terminal to a desired wireless communication network without relying on a specific communication method such as SMS, while minimizing the effort required for key management and ensuring security. [Brief explanation of the drawings]
[0017] [Figure 1] FIG. 1 is a diagram illustrating an example of a schematic configuration of a communication system S. [Figure 2] FIG. 2 is a diagram illustrating an example of a schematic configuration of a terminal T. [Figure 3] 10 is a sequence diagram showing an example of processing by the control unit 5 and SIM of the terminal T in the first embodiment. FIG. [Figure 4] FIG. 10 is a sequence diagram illustrating an example of processing by the control unit 5 and SIM of the terminal T in the second embodiment. [Figure 5]FIG. 11 is a sequence diagram illustrating an example of processing by the control unit 5 and SIM of the terminal T in the third embodiment. DETAILED DESCRIPTION OF THE INVENTION
[0018] DETAILED DESCRIPTION OF THE PREFERRED EMBODIMENTS Hereinafter, preferred embodiments of the present invention will be described in detail with reference to the accompanying drawings. The preferred embodiments described below are embodiments in which the present invention is applied to a communication system.
[0019] [1. Overview of Communication System S] First, a schematic configuration of a communication system S according to this embodiment will be described with reference to Fig. 1. Fig. 1 is a diagram showing an example of the schematic configuration of the communication system S. As shown in Fig. 1, the communication system S includes a public wireless communication network NW1, a private wireless communication network NW2, a private wireless communication network NW3, an external device G, and a terminal T. Note that, in the example of Fig. 1, one external device G and one terminal T are shown, but in reality, there are many of each. In the example of Fig. 1, the communication range of the public wireless communication network NW1 (within the ellipse represented by a curve) includes the communication range of the private wireless communication network NW2 (within the ellipse represented by a curve) and the communication range of the private wireless communication network NW3 (within the ellipse represented by a curve). In addition, the communication range of the private wireless communication network NW2 and the communication range of the private wireless communication network NW3 partially overlap.
[0020] The public wireless communication network NW1 is a mobile communication network built by a mobile communication carrier that provides mobile communication services, and provides voice communication, SMS communication, and data communication. On the other hand, the private wireless communication networks NW2 and NW3 are mobile communication networks other than the public communication networks provided by the mobile communication carrier, for example, mobile communication networks built in a specific area (e.g., a facility) by a company or organization other than the mobile communication carrier, and provide data communication. The public wireless communication network NW1 and the private wireless communication networks NW2 and NW3 each comprise a wireless network including base stations and a core network including a core, and authentication processing for connection to the wireless communication network is performed using a SIM provided by the network builder (i.e., the mobile communication carrier or a company or organization other than the mobile communication carrier).
[0021] The external device G is installed as a gateway near an entrance / exit of a specific area of a company or organization other than the mobile communication carrier (for example, near an entrance / exit of a facility), and is capable of performing short-range wireless communication with a terminal T within a communication range of, for example, several meters to several tens of meters. For short-range wireless communication, for example, NFC (Near Field Communication), Bluetooth (registered trademark), or UWB (Ultra Wide Band) technology may be used. The external device G stores a key pair consisting of a private key and a public key unique to the external device G.
[0022] Then, the external device G transmits a command including instruction information indicating an instruction to connect to a predetermined wireless communication network out of the public wireless communication network NW1, the private wireless communication network NW2, and the private wireless communication network NW3 to the terminal T (i.e., the terminal T that has entered the communication range of the short-range wireless communication) via short-range wireless communication. Here, the predetermined wireless communication network is, for example, the private wireless communication network NW2 or the private wireless communication network NW3, and is set in the SIM by the network builder. Note that the instruction information is sufficient as long as it indicates an instruction to connect to the predetermined wireless communication network, and does not need to indicate information (e.g., identification information) for identifying the predetermined wireless communication network.
[0023] Furthermore, when transmitting the command, the external device G generates signature information by signing the instruction information with a private key included in the key pair (i.e., encrypting the instruction information with the private key), and transmits a command including the instruction information and the signature information to the terminal T. Furthermore, the external device G may transmit a command including a counter value together with the instruction information and signature information to the terminal T. The counter value is a value that is incremented with each transmission. For example, the counter value at the time of the first transmission is "1," the counter value at the time of the second transmission is "2," and so on. Note that, if the external device G can identify the terminal T with which it will communicate with in near-field wireless communication, it may manage a history of counter values transmitted to the terminal T and calculate a counter value to be transmitted to the terminal T based on the history each time it transmits to the terminal T. For example, if the counter value previously transmitted to the terminal T was "1," the counter value obtained by incrementing the previous counter value by one is transmitted to the terminal T in this communication.
[0024] FIG. 2 is a diagram showing an example of the schematic configuration of terminal T. As shown in FIG. 2, terminal T is configured to include an I / F unit 1, a wireless communication unit 2, a storage unit 3, an operation / display unit 4, and a control unit 5. Terminal T is, for example, a mobile terminal such as a smartphone. Terminal T is equipped with a SIM. The SIM is an example of an electronic information storage medium of the present invention, and may be detachably mounted in terminal T as an IC (Integrated Circuit) card, or may be an eUICC (Embedded Universal Integrated Circuit Card) mounted (for example, soldered) on a board so that it cannot be easily removed or replaced from terminal T. Terminal T may also be equipped with a fingerprint sensor. The fingerprint sensor reads a fingerprint from the pad of a finger of a user of terminal T and outputs the fingerprint information (an example of user biometric information) to control unit 5. I / F unit 1 serves as an interface with the SIM. Such an interface is preferably an ISO7816 interface. However, I / F unit 1 may also be equipped with an SPI (Serial Peripheral Interface) or an I / F (Interface) 2 There may be cases where an Inter-Integrated Circuit (C) is applied. Note that the control unit 5 and the SIM communicate via the I / F unit 1 in accordance with, for example, an APDU (Application Protocol Data Unit) protocol.
[0025] The wireless communication unit 2 is composed of a first communication module for connecting (switchably connecting) to any one of the public wireless communication network NW1, the private wireless communication network NW2, and the private wireless communication network NW3, and a second communication module for performing short-range wireless communication with an external device G. The first communication module has a modem that detects the wireless communication network (any of NW1 to NW3) and is capable of performing wireless communication with a base station of the detected wireless communication network. In an area where the coverage areas of the multiple wireless communication networks overlap, the wireless communication unit 2 maintains connection to the currently connected wireless communication network (e.g., the public wireless communication network NW1). For example, switching from the public wireless communication network NW1 to the private wireless communication network NW2 is performed by a REFRESH command from the SIM. Here, the REFRESH command is a proactive command specified by 3GPP (described in ETSI TS 102 223 and 3GPP TS 31.111).
[0026] On the other hand, the second communication module performs short-range wireless communication with the external device G when a user carrying the terminal T enters a specific area (e.g., a building), and receives commands including the instruction information, signature information, etc. transmitted from the external device G. The storage unit 3 is composed of, for example, a non-volatile memory, and stores an operating system and applications. The operation and display unit 4 has an input function for receiving input from the user and a display function for displaying various information on a display (e.g., a touch panel). The operation and display unit 4 outputs a PIN (an example of an input value) input by the user to the control unit 5.
[0027] The control unit 5 corresponds to the UE defined by 3GPP, and is configured by, for example, a CPU (Central Processing Unit), RAM (Random Access Memory), and ROM (Read Only Memory). The control unit 5 performs control for connecting to the wireless communication network (any of NW1 to NW3) via the wireless communication unit 2. The control unit 5 also performs contactless communication (short-range wireless communication) with the external device G via the wireless communication unit 2, and receives commands including the instruction information, signature information, and the like transmitted from the external device G. Furthermore, the control unit 5, as an information processing unit of the terminal T, performs contact communication with the SIM via the I / F unit 1. The information processing unit of the terminal T may be configured by software or hardware.
[0028] Then, when the control unit 5 receives a command including the instruction information, signature information, and the like from the external device G, it transmits the command including the instruction information, signature information, and the like to the SIM via the I / F unit 1. Furthermore, when the control unit 5 receives a REFRESH command from the SIM via the I / F unit 1, it performs control to connect to the wireless communication network (any of NW1 to NW3) indicated in the REFRESH command. For example, the control unit 5 outputs a control command to the wireless communication unit 2 to connect to the wireless communication network (any of NW1 to NW3) indicated in the REFRESH command. Here, as described above, for example, if the REFRESH command is received while the terminal T is connected to the public wireless communication network NW1, the connection is switched from the public wireless communication network NW1 to, for example, the private wireless communication network NW2. In this case, the REFRESH command can be said to be a command for switching from the wireless communication network to which the terminal T is currently connected to a predetermined wireless communication network. Note that the REFRESH command may also switch the connection from the private wireless communication network NW2 to the private wireless communication network NW3.
[0029] The SIM is compatible with the UICC defined by 3GPP, and as shown in FIG. 2, includes an I / F unit 11, a RAM 12, a ROM 13, an NVM (Nonvolatile Memory) 14, and a CPU 15. The I / F unit 11 serves as an interface with the control unit 5 of the terminal T. The NVM 14 (an example of a storage means) is a nonvolatile memory such as a flash memory. A public key unique to the external device G is stored in the NVM 14. The NVM 14 may be provided with a counter (storage area) that stores the counter value described above. Furthermore, the NVM 14 stores a USAT (User Subscriber Identity Module Application Toolkit) application executed by the CPU 15. The USAT application includes a USAT framework, an RFM (Remote File Management), and a USAT applet.
[0030] The USAT framework has a function of communicating with the control unit 5 via the I / F unit 11. The RFM and USAT applet each run on the USAT framework. The RFM has a function of writing and reading data files stored in the NVM 14 in response to a request from the USAT framework. Data files are stored in the NVM 14 for each of the wireless communication networks NW1 to NW3. Each data file contains authentication information and telephone numbers used to connect to each of the wireless communication networks NW1 to NW3. The USAT applet has a function of responding with a REFRESH command for connecting to a predetermined wireless communication network (one of NW1 to NW3) in response to a command containing instruction information from the external device G. The REFRESH command is set in the USAT applet in advance, for example, and contains information (e.g., identification information) for identifying the predetermined wireless communication network.
[0031] The USAT applet functions as the receiving means, authenticating means, and transmitting means of the present invention in communication with the control unit 5. Specifically, when the USAT applet receives a command including the instruction information and signature information from the control unit 5 via the I / F unit 11, the USAT applet performs signature verification using the public key stored in NVM 14 and the signature information included in the command in accordance with the instruction information. If the signature verification is successful (i.e., the signature information can be successfully decrypted using the public key), the USAT applet transmits a REFRESH command to the control unit 5 via the I / F unit 11 to connect to a predetermined wireless communication network (one of NW1 to NW3).
[0032] Alternatively, when the USAT applet receives a command including the counter value along with the instruction information and signature information from the control unit 5 via the I / F unit 11, it performs signature verification and determines whether the counter value included in the command is greater than the counter value held in the counter. This makes it possible to counter attacks in which instruction information, etc., is sent multiple times. If the USAT applet determines that the signature verification is successful and that the counter value included in the command is greater than the counter value held in the counter, it transmits the REFRESH command to the control unit 5 via the I / F unit 11.
[0033] In the above example, the SIM is configured to transmit a REFRESH command to the control unit 5 of terminal T in response to instruction information transmitted by the external device G. However, as another example, the SIM may be configured to transmit a REFRESH command to the control unit 5 of terminal T in response to an operation by the user of terminal T. In this case, first identification information used for connecting to a predetermined wireless communication network is pre-stored in the NVM 14. Examples of the first identification information include a random number (random value) generated by the SIM, a PIN entered by the user of terminal T, and fingerprint information of the user. After the first identification information is stored in the NVM 14, the USAT applet receives second identification information transmitted from the control unit 5 of terminal T in response to an operation by the user of terminal T via the I / F unit 11 and the USAT framework, and performs authentication using the first identification information stored in the NVM 14 and the received second identification information. If the authentication is successful (for example, the first identification information and the second identification information match), the USAT applet transmits the REFRESH command to the control unit 5 via the I / F unit 11 and the USAT framework.
[0034] [2. Operation of communication system S] Next, the operation of the communication system S will be described in the first to third embodiments.
[0035] Example 1 First, a first embodiment will be described in which a REFRESH command is transmitted from the SIM to the control unit 5 of the terminal T in response to instruction information transmitted by the external device G. FIG. 3 is a sequence diagram showing an example of processing by the control unit 5 of the terminal T and the SIM in the first embodiment. In the first embodiment, when the terminal T enters a specific area, the terminal T receives a command transmitted from the external device G via short-range wireless communication, the command including the instruction information, signature information, and counter value. Note that the public key unique to the external device G may be stored in advance in the NVM 14 of the SIM, or may be received as the temporary public key included in the command together with the instruction information, signature information, and counter value.
[0036] When the control unit 5 of the terminal T receives a command including the instruction information, signature information, and counter value from the external device G via the wireless communication unit 2, the control unit 5 transmits the command to the SIM via the I / F unit 1 (step S1). The command depends on the communication method (for example, UWB). The control unit 5 of the terminal T may convert the protocol of the received command to that for the SIM and transmit the command.
[0037] Next, when the USAT applet (Toolkit AP) of the SIM receives the command from the control unit 5 via the I / F unit 11, it performs signature verification using the public key of the external device G and the signature information included in the received command, and determines whether the counter value included in the command is greater than the counter value held in the counter (counter value determination) (step S2). If the signature verification is successful (i.e., the signature information can be successfully decrypted using the public key) and it is determined that the counter value included in the command is greater than the counter value held in the counter, the USAT applet transmits a REFRESH command (send()) to the USAT framework (step S3). Note that if the signature verification fails (e.g., the signature information cannot be successfully decrypted using the public key) or if it is determined that the counter value included in the command is not greater than the counter value held in the counter, error processing is performed, and a response indicating an error is transmitted to the control unit 5, for example.
[0038] Next, upon receiving a REFRESH command from the USAT applet, the USAT framework transmits a 91XX response to the control unit 5 via the I / F unit 11 (step S4). Here, "91XX" is a status word indicating that data (REFRESH) with a data length of "XX" is present in the SIM. Next, upon receiving the 91XX response from the SIM, the control unit 5 transmits a FETCH command to the SIM via the I / F unit 1 (step S5). Next, upon receiving the FETCH command from the control unit 5, the USAT framework transmits a REFRESH command to the control unit 5 via the I / F unit 11 (step S6). Next, upon receiving the REFRESH command from the SIM, the control unit 5 performs control to connect to the wireless communication network (one of NW1 to NW3) indicated in the REFRESH command (step S7). Next, the control unit 5 transmits a TERMINAL RESPONSE command to the SIM via the I / F unit 1 (step S8). Next, upon receiving the TERMINAL RESPONSE command from the control unit 5, the USAT framework transmits a 9000 response to the control unit 5 via the I / F unit 11 (step S9), where "9000" is a status word indicating normal termination.
[0039] Example 2 Next, a second embodiment will be described in which a REFRESH command is transmitted from the SIM to the control unit 5 in response to an operation by a user of the terminal T. FIG. 4 is a sequence diagram illustrating an example of processing by the control unit 5 and the SIM of the terminal T in the second embodiment. In the second embodiment, a random number (an example of first identification information) dynamically generated by the control unit 5 of the terminal T is stored in advance in the NVM 14 of the SIM. This random number is generated by the SIM (for example, a USAT applet) in response to an operation by the user of the terminal T. Then, the SIM embeds the generated random number in a SET UP MENU command and provides the generated random number to the control unit 5. Here, the SET UP MENU command is a proactive command defined by 3GPP, and one of a plurality of menu items provided by the SET UP MENU command is set by the user. The random number generated by the SIM is stored in the storage unit 3 in association with an identifier of the menu set by the user, and is also stored in the NVM 14 in association with the identifier of the menu. In the second embodiment, when the terminal T receives the instruction information transmitted from the external device G via short-range wireless communication when the terminal T enters a specific area, the control unit 5 of the terminal T may display a message on the operation / display unit 4 prompting the terminal T to switch the wireless communication network.
[0040] After the random number is stored in the SIM, when the user of terminal T operates the operation / display unit 4 to select the set menu, the control unit 5 of terminal T transmits an ENVELOPE (MENU SELECTION) command including the identifier of the selected menu and the random number (an example of second identification information) to the SIM via the I / F unit 1 (step S11). Here, the random number included in the ENVELOPE (MENU SELECTION) command is the random number stored in association with the identifier of the menu set by the user. Next, upon receiving the ENVELOPE command from the control unit 5, the USAT framework of the SIM calls the USAT applet (process Toolkit()) (step S12). The USAT applet performs authentication using the random number stored in the NVM 14 and the random number included in the received command (step S13). Then, if the authentication is successful (i.e., the random numbers match), the USAT applet transmits the REFRESH command to the USAT framework (step S3), as in the first embodiment, and the subsequent processing is performed. If the authentication fails (for example, the random numbers do not match), an error process is performed, and a response indicating an error is sent to the control unit 5, for example.
[0041] Example 3 Next, a third embodiment will be described in which a REFRESH command is transmitted from the SIM to the control unit 5 in response to an operation by a user of the terminal T. FIG. 5 is a sequence diagram illustrating an example of processing by the control unit 5 and the SIM of the terminal T in the third embodiment. In the third embodiment, a PIN (an example of first identification information) input by a user of the terminal T is pre-stored in the NVM 14 of the SIM. Note that, instead of the PIN, the user's fingerprint information may be pre-stored in the NVM 14. This PIN is not particularly limited, but is written to the SIM by some method (for example, a special terminal installed in a security factory or a specific department of a company). In other words, it is assumed that the PIN is known only to the user of the special terminal (the same person as the user of the terminal T) and the SIM, and that the special terminal does not know the PIN. Note that, in the third embodiment as well, when the terminal T receives the instruction information transmitted from the external device G via short-range wireless communication when the terminal T enters a specific area, the control unit 5 of the terminal T may display a message prompting the switching of the wireless communication network on the operation / display unit 4.
[0042] After the PIN is stored in the SIM, the user sets one of the menu items provided by the SET UP MENU command from the SIM, as in the second embodiment. When the user of terminal T then operates the operation and display unit 4 to select the set menu, the control unit 5 of terminal T transmits an ENVELOPE (MENU SELECTION) command including the identifier of the selected menu to the SIM via the I / F unit 1 (step S21). Upon receiving the ENVELOPE command from the control unit 5, the USAT framework of the SIM calls the USAT applet (process Toolkit()) (step S22), and the USAT applet transmits a response (send()) to the USAT framework (step S23).
[0043] Next, upon receiving a response from the USAT applet, the USAT framework transmits a 91XX response to the control unit 5 via the I / F unit 11 (step S24). Next, upon receiving the 91XX response from the SIM, the control unit 5 transmits a FETCH command to the SIM via the I / F unit 1 (step S25). Next, upon receiving the FETCH command from the control unit 5, the USAT framework transmits a GET INPUT command to the control unit 5 via the I / F unit 11 (step S26). Here, the GET INPUT command is a proactive command defined by 3GPP. Next, upon receiving the GET INPUT command from the SIM, the control unit 5 displays a request for the user to input a PIN (which may be fingerprint information) on the operation / display unit 4, and transmits a TERMINAL RESPONSE command including the PIN entered by the user to the SIM via the I / F unit 1 (step S27).
[0044] Next, upon receiving the TERMINAL RESPONSE command from the control unit 5, the USAT framework of the SIM passes the PIN included in the TERMINAL RESPONSE command to the USAT applet (return from send()) (step S28), and the USAT applet performs authentication using the PIN stored in NVM 14 and the PIN passed from the USAT framework (step S29). If the authentication is successful (i.e., the PINs match), the USAT applet sends the above-mentioned REFRESH command to the USAT framework (step S3), as in the first embodiment, and the subsequent processing is performed. Note that if the authentication fails (for example, the PINs do not match), error processing is performed, and a response indicating an error is sent to the control unit 5, for example.
[0045] As described above, according to the above embodiment, when the SIM installed in the terminal T receives the instruction information and signature information, etc. from the external device G via the control unit 5 of the terminal T, it performs signature verification using a public key unique to the external device G and the signature information in accordance with the instruction information, and if the signature verification is successful, it is configured to send a REFRESH command to the control unit 5 to connect to a specified wireless communication network.Therefore, it is possible to connect the terminal T to a desired wireless communication network without relying on a specific communication method such as SMS, and while minimizing the effort required for key management and ensuring security.
[0046] Furthermore, according to the above embodiment, the SIM installed in terminal T is configured to pre-store first identification information used to connect to a specified wireless communication network among multiple wireless communication networks, and when it receives second identification information sent from the control unit 5 of terminal T in response to the operation of the user of terminal T, it performs authentication using the stored first identification information and the received second identification information, and if the authentication is successful, it sends a REFRESH command to the control unit 5 to connect to the specified wireless communication network.Therefore, it is possible to connect terminal T to a desired wireless communication network without relying on a specific communication method such as SMS, and while minimizing the effort of key management and ensuring security.
[0047] In the above embodiment, an example has been described in which one public wireless communication network is included among multiple wireless communication networks, but the present invention is also applicable to cases in which multiple public wireless communication networks are included. In this case, too, the connection can be switched from one public wireless communication network to another public wireless communication network by the sequence described with reference to Figures 3 to 5. Furthermore, in the above embodiment, the application of the control unit 5 and the USAT applet of the SIM may be configured to work together directly without going through the USAT framework. [Explanation of symbols]
[0048] 1 I / F section 2. Wireless Communication Unit 3 Storage section 4 Operation / display section 5. Control section 11 I / F section 12 RAM 13 ROM 14 NVM 15 CPU T-Terminal G External device NW1 Public wireless communication network NW2, NW3 Private wireless communication network S Communication System
Claims
1. An electronic information storage medium mounted on a terminal connectable to any one of a plurality of different wireless communication networks, a storage means for storing a public key included in a key pair unique to the external device; a receiving means for receiving instruction information indicating an instruction to connect to a predetermined wireless communication network among the plurality of wireless communication networks and signature information generated by signing the instruction information with a private key included in the key pair, the receiving means receiving the instruction information and the signature information transmitted from the external device via an information processing unit of the terminal; an authentication means for performing signature verification using the public key and the signature information in response to the instruction information; a transmitting means for transmitting a command to connect to the predetermined wireless communication network to an information processing unit of the terminal when the signature verification is successful; An electronic information storage medium comprising:
2. a counter for storing a counter value transmitted from the information processing unit; the receiving means receives the counter value together with the instruction information and the signature information; the authentication means determines whether the counter value received by the receiving means is greater than the counter value held in the counter; The electronic information storage medium according to claim 1, characterized in that the transmitting means transmits a command to connect to the specified wireless communication network to the information processing unit of the terminal when it is determined that the signature verification is successful and the counter value received by the receiving means is greater than the counter value stored in the counter.
3. The electronic information storage medium according to claim 1 or 2, characterized in that the instruction information and the signature information are received by the terminal via short-range wireless communication performed between the terminal and the external device when a user carrying the terminal enters a specific area.
4. 4. The electronic information storage medium according to claim 1, wherein the predetermined wireless communication network is a private wireless communication network other than a public communication network provided by a mobile communication carrier.
5. 4. The electronic information storage medium according to claim 1, wherein the command is a command for switching the terminal from a wireless communication network to which the terminal is currently connected to the predetermined wireless communication network.
6. A wireless communication network connection method performed by an information processing unit of a terminal connectable to any one of a plurality of different wireless communication networks and an electronic information storage medium installed in the terminal, comprising: storing, on the electronic information storage medium, a public key included in a key pair unique to the external device; an information processing unit of the terminal receiving, from the external device, instruction information indicating an instruction to connect to a predetermined wireless communication network among the plurality of wireless communication networks and signature information generated by signing the instruction information with a private key included in the key pair, and transmitting the received instruction information and signature information to the electronic information storage medium; a step of performing signature verification by the electronic information storage medium using the public key and the signature information when the electronic information storage medium receives the instruction information and the signature information from the information processing unit of the terminal; a step of transmitting a command from the electronic information storage medium to an information processing unit of the terminal to connect to the predetermined wireless communication network when the signature verification is successful; an information processing unit of the terminal connecting to the predetermined wireless communication network when the command is received from the electronic information storage medium; A wireless communication network connection method comprising:
Citation Information
Patent Citations
IMSI switching method and device
JP2013042491A
Message transmission system
JP2017076930A
METHOD AND APPARATUS FOR MANAGING TERMINAL PROFILES IN A WIRELESS COMMUNICATION SYSTEM - Patent application
JP2018512822A
Radio communication equipment and control method thereof
JP2019096949A